Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5cj6-x2gg-fq5g

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page. A remote attacker that can access the remote management login page can manipulate the POST request in such a manner as to access some administrator-only pages such as tools_admin.asp without credentials.

D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page. A remote attacker that can access the remote management login page can manipulate the POST request in such a manner as to access some administrator-only pages such as tools_admin.asp without credentials.

EPSS

Процентиль: 97%
0.33804
Средний

9.8 Critical

CVSS3

Дефекты

CWE-20
CWE-294

Связанные уязвимости

CVSS3: 9.8
nvd
около 8 лет назад

D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page. A remote attacker that can access the remote management login page can manipulate the POST request in such a manner as to access some administrator-only pages such as tools_admin.asp without credentials.

EPSS

Процентиль: 97%
0.33804
Средний

9.8 Critical

CVSS3

Дефекты

CWE-20
CWE-294